VendorsBlack Duck
Black Duck
Cybersecurity reports and statistics published by Black Duck
8 categories6 reports
Research Reports
Reports and publications from Black Duck
Recent Statistics & Reports
Mean vulnerabilities per codebase increased by 107% year-over-year.
5/27/2026•
VulnerabilitiesOpen Source Security
Open source component counts increased by 30% year-over-year.
5/27/2026•
Open SourceDependency ManagementOpen Source Security
68% of audited codebases contain license conflicts, a 12 percentage-point increase from 56% the previous year.
5/27/2026•
LicensingOpen SourceOpen Source Security
76% of organizations check AI-generated code for security risks.
5/27/2026•
AI-Generated CodeAI RiskOpen Source Security
54% of organizations evaluate AI-generated code for IP and license risks.
5/27/2026•
LicensingAI RiskAI-Generated Code
56% of organizations assess quality issues in AI-generated code.
5/27/2026•
Software QualityAI RiskAI-Generated Code
The number of files per codebase grew by 74% year-over-year.
5/27/2026•
Codebase SizeSoftware CompositionOpen Source Security
24% of organizations perform comprehensive IP, license, security, and quality evaluations for AI-generated code.
5/27/2026•
AI-Generated CodeAI RiskOpen Source Security
98% of codebases contain open source components.
5/27/2026•
Open SourceOpen Source Security
Streamlining of responsible vulnerability disclosure grew by more than 40%.
2/9/2026•
Vulnerability DisclosureRegulatory ComplianceApplication Security
Nearly 30% more organizations now produce SBOMs to meet transparency requirements.
2/9/2026•
SBOMRegulatory Compliance
Teams using attack intelligence to track emerging AI vulnerabilities increased by 10%.
2/9/2026•
AI SecurityThreat IntelligenceApplication Security
Application of custom rules to automated code review tools to catch issues unique to AI-generated code increased by 10%.
2/9/2026•
AI SecurityCode ReviewDeveloper Tools
Organizations delivering expertise through open collaboration channels increased by 29%.
2/9/2026•
Collaboration
Use of risk-ranking methods to determine where LLM-generated code is safe to deploy increased by 12%.
2/9/2026•
AI SecurityRisk ManagementApplication Security
Establishment of standardized technology stacks rose by more than 40%.
2/9/2026•
Technology StackApplication Security
Automated verification of infrastructure security surged by more than 50%.
2/9/2026•
Infrastructure SecurityAutomationApplication Security
95% of surveyed organizations reported using AI tools in software development.
1/1/2026•
AI ToolsSoftware Development
Organizations that effectively track and manage open source dependencies are 85% more prepared to secure open source software compared to the overall average of 57%.
1/1/2026•
Open SourceSoftware SecurityOpen Source Dependencies
63% of respondents that prioritize SBOM validation say they're highly prepared to evaluate third-party software.
1/1/2026•
Third-Party Software SecuritySoftware Supply ChainSBOM Validation
Showing 1-20 of 51 results